Bump symfony/yaml from 2.6.4 to 5.4.52 - #2
Conversation
Bumps [symfony/yaml](https://github.com/symfony/Yaml) from 2.6.4 to 5.4.52. - [Release notes](https://github.com/symfony/Yaml/releases) - [Changelog](https://github.com/symfony/yaml/blob/8.2/CHANGELOG.md) - [Commits](symfony/yaml@v2.6.4...v5.4.52) --- updated-dependencies: - dependency-name: symfony/yaml dependency-version: 5.4.52 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
composer.lockPackage changes
Settings · Docs · Powered by Private Packagist |
|
🤖 Dependabot PR processing skill — risk assessment Acting on behalf of Joost Faassen. DecisionDo not merge automatically — assessed risk: high What changed
Why this was not merged automatically
Checks considered
Automated assessment by the Dependabot PR processing skill. Detail stays in this comment; the merge commit message is kept short on purpose. |
3 similar comments
|
🤖 Dependabot PR processing skill — risk assessment Acting on behalf of Joost Faassen. DecisionDo not merge automatically — assessed risk: high What changed
Why this was not merged automatically
Checks considered
Automated assessment by the Dependabot PR processing skill. Detail stays in this comment; the merge commit message is kept short on purpose. |
|
🤖 Dependabot PR processing skill — risk assessment Acting on behalf of Joost Faassen. DecisionDo not merge automatically — assessed risk: high What changed
Why this was not merged automatically
Checks considered
Automated assessment by the Dependabot PR processing skill. Detail stays in this comment; the merge commit message is kept short on purpose. |
|
🤖 Dependabot PR processing skill — risk assessment Acting on behalf of Joost Faassen. DecisionDo not merge automatically — assessed risk: high What changed
Why this was not merged automatically
Checks considered
Automated assessment by the Dependabot PR processing skill. Detail stays in this comment; the merge commit message is kept short on purpose. |
Bumps symfony/yaml from 2.6.4 to 5.4.52.
Release notes
Sourced from symfony/yaml's releases.
Changelog
Sourced from symfony/yaml's changelog.
... (truncated)
Commits
b0b2705[Yaml] Harden the Parser::cleanup() regexes against catastrophic backtracking5a351ff[Yaml] Bound collection-alias resolution in the parserb02ba66[Yaml] Bound recursion depth in the parsera454d47Add PR template and auto-close PR on subtree split repositories7025b96parse empty sequence elements as null62f96e1🐛 throw ParseException on invalid date81cad0cRevert "minor #54653 Auto-close PRs on subtree-splits (nicolas-grekas)"bc780e1call substr() with integer offsetsa38ba0bAuto-close PRs on subtree-splitse78db7fApply php-cs-fixer fix --rules nullable_type_declaration_for_default_null_valueDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.